Skip to main content
Pleo

Senior Application Security Manager

RemoteUnited Kingdom only
Published
Role
Security
Experience
Lead
Employment
Full-time
Company size
Mid-size
Salary not disclosed
Check eligibility

Open to GB only. Set where you work from to check your eligibility.

No BS summary

Senior AppSec manager with 10+ years in application security and information security strategy, ideally from senior security engineering into management. Needs hands-on AppSec depth, vulnerability management, risk-based triage, AI/automation, mentoring, and compliance-heavy experience. Must be physically based in one of the advert locations with right to work; no visa sponsorship.

Required languages

English

What you'll do

  • Own vulnerability management end to end, covering reporting, triage, mitigation, and the long-term strategy for application security as a department.
  • Build a structured, risk-ranked approach to remediation, so the organisation knows what to fix first and why.
  • Establish clear, company-wide reporting on our vulnerability posture, giving leadership the data-driven visibility they need.
  • Set and deliver an AppSec roadmap, bringing delivery expectations and accountability to a team that hasn't had them.
  • Partner with engineering squads as customers rather than gatekeeping them, embedding proactive security processes into how they already work.
  • Multiply your team's impact through automation and AI, so coverage scales faster than headcount.
  • Grow and mentor engineers, coaching them toward staff-level capability and building their confidence along the way.
  • Support Pleo's compliance obligations across ISO27001, PCI-DSS, GDPR, and the regulatory expectations of each market we operate in, from a security vulnerability perspective.
  • Reduce our attack surface through technical controls, policy, and AI enablement, addressing both external threats and internal risk.
  • Contribute to the broader Cybersecurity team, staying connected with ongoing initiatives and helping shape our 2027 KPIs.
  • Get hands-on with Pleo's application security landscape, understanding our attack surface across payment systems and multi-region infrastructure, and forming your own view of where the real risk sits.
  • Stand up clear vulnerability reporting and a risk-ranked remediation approach, and get key vulnerabilities patched proactively ahead of our next compliance audit.
  • Build trust with engineering squads and start shifting the security culture, so teams come to you early rather than late.
  • Integrate into the Cybersecurity team, connecting with DevSecOps, SecOps, and Risk & Compliance, and begin shaping the roadmap and KPIs that carry the program into 2027.

What they require

  • 10+ years of experience steering application security and wider information security strategy in a compliance-heavy environment.
  • A background as a senior security engineer who moved into management, with enough technical depth that you're still credible and still hands-on.
  • A track record of mentoring and growing engineers, and of keeping a team accountable without micromanaging it.
  • Demonstrated experience turning signal into prioritised action through risk-based triage.
  • Experience using AI and automation to scale security coverage, rather than solving everything through headcount or process.
  • The ability to shape culture outside your own team, influencing engineering squads without formal authority over them.
  • Comfort in a fast-moving, complex, ever-evolving environment, where you're self-directed and proactive.
  • Preferred: Exposure to fintech compliance requirements is a strong advantage.
  • Preferred: Backgrounds we also look at include DevSecOps and platform security leads with real AppSec depth.
  • You want a fast, visible impact on a program with real room to improve, without having to fight for basic tooling and process first.
  • You treat developers as customers and get satisfaction from security becoming an enabler rather than a blocker.
  • You like being a player-coach, staying close to the technical work while growing the people around you.
  • You're motivated by high leverage and low bureaucracy, and you'd rather build the system than personally do every task.
  • You're not looking to step away from technical work entirely at this level.
  • You do not prefer to lead through mandate and process rather than partnership and example.
  • You're not sceptical of automation, AI, or of leaning on signal from partner teams.
  • You will need to be physically based in the country of your choice with a valid right to work.
  • Please submit your application in English.

Benefits

  • Your own Pleo card (no more out-of-pocket spending!)
  • Lunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your local office
  • Comprehensive private healthcare - depending on your location, coverage options include Vitality, Alan or Médis
  • We offer 25-28 days of holiday (depending on your location) + public holidays
  • For our Team, we offer both hybrid and fully remote working options
  • Option to purchase 5 additional days of holiday through a salary sacrifice
  • We use MyndUp to give our employees access to free mental health and well-being support with great success so far
  • Paid parental leave - we want to make sure that we're supportive of families and help you feel that you don't have to compromise your family due to work
  • We're committed to helping you develop your career, whether that means taking on bigger projects, stepping into broader leadership, or acquiring new skills.

Pleo builds spend solutions that make managing money seamless for finance teams and employees.

🇬🇧 United KingdomFintechMid-size

Details

Visa sponsorshipNo
Salary not disclosed